SUBSCRIBE
SUBSCRIBE
EXPLORE +
  • About infoDOCKET
  • Academic Libraries on LJ
  • Research on LJ
  • News on LJ
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Libraries
    • Academic Libraries
    • Government Libraries
    • National Libraries
    • Public Libraries
  • Companies (Publishers/Vendors)
    • EBSCO
    • Elsevier
    • Ex Libris
    • Frontiers
    • Gale
    • PLOS
    • Scholastic
  • New Resources
    • Dashboards
    • Data Files
    • Digital Collections
    • Digital Preservation
    • Interactive Tools
    • Maps
    • Other
    • Podcasts
    • Productivity
  • New Research
    • Conference Presentations
    • Journal Articles
    • Lecture
    • New Issue
    • Reports
  • Topics
    • Archives & Special Collections
    • Associations & Organizations
    • Awards
    • Funding
    • Interviews
    • Jobs
    • Management & Leadership
    • News
    • Patrons & Users
    • Preservation
    • Profiles
    • Publishing
    • Roundup
    • Scholarly Communications
      • Open Access

August 8, 2018 by Gary Price

National Archives (NARA): Inspector General Releases Special Report on Compliance with DHS Email and Web Security Directive

August 8, 2018 by Gary Price

From the National Archives and Records Administration (NARA) Inspector General:

2018-08-09_13-07-47Security of federal websites significantly impacts website users. According to DHS improving federal website security through the implementation of security standards adopted by industry, allows federal agencies to ensure the integrity and confidentiality of internet-delivered data, minimize unsolicited email, and better protect users from phishing emails that appear to come from government-owned systems. DHS and the federal government are improving the security of government-owned systems including websites through the use of BODs. One such BOD is 18-01, Enhance Email and Web Security.
BOD 18-01 is comprised of two components. The first is email security that requires agencies to implement STARTTLS and improve email authentication by implementing Domain-based Message Authentication, Reporting & Conformance (DMARC). The second is a supplement to Office of Management and Budget’s (OMB) Memorandum (M) 15-13, which requires all existing Federal websites and web services to be accessible through a secure connection (HTTPS-only, with HSTS). However, BOD 18-01 takes security a step further by requiring agencies to remove support for known-weak cryptographic protocols and ciphers.
Overall, NARA is making significant progress toward implementing BOD 18-01 with the .gov websites and emails. Based on the June 9, 2018 cyberhygiene3 scans, NARA is 94% compliant with the website portion and 73% compliant with the email portion of the BOD. However, there are two categories, one in websites and one in emails, that are not incorporated into the compliance percentages as required. As a result, NARA cannot ensure the accuracy of the scan results indicating 94% of websites and 73% of emails are compliant with BOD 18-01.

Read the Complete Report (3 pages; PDF)

Filed under: Archives and Special Collections, Data Files, Management and Leadership, News, Patrons and Users

SHARE:

About Gary Price

Gary Price (gprice@gmail.com) is a librarian, writer, consultant, and frequent conference speaker based in the Washington D.C. metro area. He earned his MLIS degree from Wayne State University in Detroit. Price has won several awards including the SLA Innovations in Technology Award and Alumnus of the Year from the Wayne St. University Library and Information Science Program. From 2006-2009 he was Director of Online Information Services at Ask.com.

ADVERTISEMENT

Archives

Job Zone

ADVERTISEMENT

Related Infodocket Posts

ADVERTISEMENT

FOLLOW US ON X

Tweets by infoDOCKET

ADVERTISEMENT

This coverage is free for all visitors. Your support makes this possible.

This coverage is free for all visitors. Your support makes this possible.

Primary Sidebar

  • News
  • Reviews+
  • Technology
  • Programs+
  • Design
  • Leadership
  • People
  • COVID-19
  • Advocacy
  • Opinion
  • INFOdocket
  • Job Zone

Reviews+

  • Booklists
  • Prepub Alert
  • Book Pulse
  • Media
  • Readers' Advisory
  • Self-Published Books
  • Review Submissions
  • Review for LJ

Awards

  • Library of the Year
  • Librarian of the Year
  • Movers & Shakers 2022
  • Paralibrarian of the Year
  • Best Small Library
  • Marketer of the Year
  • All Awards Guidelines
  • Community Impact Prize

Resources

  • LJ Index/Star Libraries
  • Research
  • White Papers / Case Studies

Events & PD

  • Online Courses
  • In-Person Events
  • Virtual Events
  • Webcasts
  • About Us
  • Contact Us
  • Advertise
  • Subscribe
  • Media Inquiries
  • Newsletter Sign Up
  • Submit Features/News
  • Data Privacy
  • Terms of Use
  • Terms of Sale
  • FAQs
  • Careers at MSI


© 2026 Library Journal. All rights reserved.


© 2022 Library Journal. All rights reserved.